CVE-2022-47529
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or…
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- rsa/netwitness
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2023/Mar/26Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Apr/17
- https://community.netwitness.com/t5/netwitness-platform-security/nw-2023-04-netwitness-platform-security-advisory-cve-2022-47529/ta-p/696935Permissions Required
- https://github.com/hyp3rlinx/CVE-2022-47529
- https://hyp3rlinx.altervista.org/advisories/RSA_NETWITNESS_EDR_AGENT_INCORRECT_ACCESS_CONTROL_CVE-2022-47529.txtExploit, Third Party Advisory
- https://packetstormsecurity.com/files/171476/RSA-NetWitness-Endpoint-EDR-Agent-12.x-Incorrect-Access-Control-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2023/Mar/16Mailing List, Third Party Advisory
- https://twitter.com/hyp3rlinx/status/1639335477839790105Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Mar/26Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Apr/17
- https://community.netwitness.com/t5/netwitness-platform-security/nw-2023-04-netwitness-platform-security-advisory-cve-2022-47529/ta-p/696935Permissions Required
- https://github.com/hyp3rlinx/CVE-2022-47529
- https://hyp3rlinx.altervista.org/advisories/RSA_NETWITNESS_EDR_AGENT_INCORRECT_ACCESS_CONTROL_CVE-2022-47529.txtExploit, Third Party Advisory
- https://packetstormsecurity.com/files/171476/RSA-NetWitness-Endpoint-EDR-Agent-12.x-Incorrect-Access-Control-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2023/Mar/16Mailing List, Third Party Advisory
- https://twitter.com/hyp3rlinx/status/1639335477839790105Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.